漏洞描述 XWiki Jetty实例会公开一个上下文,允许静态访问位于 webapp/ 文件夹(特别是webapps/xwiki/WEB-INF/)中的任何文件。攻击者可以通过 URL 访问并下载可能包含敏感凭据的配置文件
相关漏洞推荐 POC CVE-2019-4061: IBM BigFix Platform - Information Disclosure POC CVE-2025-55749: XWiki - Information Disclosure POC 红海云eHR /RedseaPlatform/BossIndex.mob SQL 注入漏洞 XWiki Jetty /webapps/xwiki/WEB-INF/web.xml 文件读取漏洞(CVE-2025-55749) XWiki /rest/wikis/xwiki/query SQL 注入漏洞(CVE-2025-32969) POC CVE-2025-51991: XWiki <= 17.3.0 - Server-Side Template Injection (SSTI) POC CVE-2025-51990: XWiki – Stored Cross-Site Scripting (XSS) POC CVE-2025-32429: XWiki Platform - SQL Injection POC CVE-2025-52472: XWiki - HQL Injection XWiki Platform /bin/register/XWiki/XWikiRegister 代码执行漏洞(CVE-2024-21650) XWiki Platform /bin/ssx/Main/WebHome 目录遍历漏洞(CVE-2025-55748) (CVE-2025-55747) XWiki Platform配置文件信息泄露漏洞 (CVE-2025-52472) XWiki REST搜索URL HQL注入漏洞(orderField参数)